Dan Romero
@dwr.eth
The Ledger feature is good, actually?
28 replies
3 recasts
20 reactions
Anders
@anders
Why do you think is good? just the existence of seed phrase sharing functionality, even if encrypted, significantly expands the potential of a hack
2 replies
0 recast
1 reaction
julien
@julien51.eth
that is not true if you consider the alternative. People store their seed phrase in clear on a piece of paper...
1 reply
0 recast
0 reaction
Anders
@anders
right, but users with strong op-sec now need to worry about potential vulnerabilities from this sharing system that we all previously assumed was not possible
1 reply
0 recast
0 reaction
julien
@julien51.eth
It's still opt-in...
1 reply
0 recast
0 reaction
Cristian Padureac
@cristoforestman
The problem is security enclave by design should not allow this. If this is possible by 'opt in' it means much more possible vector attacks. A normal opt in would be if you want this, you'll need to manually copy the seedphrase to some 'shareable' less secure enclave, but here it's a hardware backdoor that can be used
0 reply
0 recast
1 reaction